Nobody Reviewed the AI You Already Bought

AI governance keeps failing before the policy gate. The riskiest AI arrived inside tools you already approved, on by default. Where to start looking.

Share
Nobody Reviewed the AI You Already Bought

The email arrived on a Tuesday, sandwiched between a calendar invite and an expense reminder. It came from a vendor whose product the organization had run for six years, the system of record for every donor, every grant, every relationship the development team depended on. The subject line announced a new assistant, powered by AI, built to draft outreach and summarize contact histories. It was already live. The email was not asking permission. It was sharing good news.

The privacy lead read it twice. Somewhere inside that product, an AI feature was now reading six years of donor records to make its summaries useful. Nobody had reviewed that. There had been no project, no intake form, no architecture review, no vendor risk assessment. The capability had simply switched on, the way a software update adds a button you never asked for.

This is where AI governance is actually failing. Not at the policy gate, where we spend most of our attention, but well before it. We have built our governance to catch the moment someone decides to bring AI into the organization. We assumed that moment would look like a decision. Increasingly, it does not. The AI you most need to review is not the AI someone proposes in a meeting. It is the AI that arrives inside the tools you approved years ago, through an update nobody read, governed by a contract you signed before the feature existed.

Consider how procurement was designed to work. A team wants a new tool. They raise a request. Security reviews it, legal reviews the contract, privacy checks the data flows, and somewhere a person signs off or does not. That gate assumes the thing being acquired is new. It fires when money changes hands or when a contract gets signed. It does not fire when a vendor you already pay flips a feature on by default in the next release. The dollars already moved. The contract is already in place. From the system's point of view, nothing happened. From a risk point of view, a great deal just did.

What happened is that your data started feeding a model. The help desk tool now suggests replies by reading past tickets, which means it is reading whatever your colleagues and the people you serve wrote in them. The meeting app now offers summaries, which means it is transcribing and storing conversations that used to vanish when the call ended. The document platform now drafts text, which means it has been given a reason to index everything you have ever written in it. None of this is inherently reckless. Much of it is genuinely useful. But all of it is processing your data in a way that was never assessed, under terms that may predate the capability entirely.

That last point deserves weight. The data processing agreement you negotiated three years ago described a certain set of activities. It named the sub-processors in use then. It set boundaries on what the vendor could do with your data. An AI feature added later can quietly stretch every one of those boundaries. There may be a new sub-processor, the model provider, that your agreement never contemplated. There may be a training question, whether your data is used to improve a model that serves the vendor's other customers, that your contract does not clearly answer. We negotiated terms for the product we bought. The product changed. The terms, in many cases, did not.

So the honest first move is not to write an AI policy. Most organizations already have one, or are drafting one, and it is aimed mostly at the AI people propose, the net-new project, the pilot someone is excited about. That policy is not wrong. It is just pointed at the wrong door. The exposure is coming in through the door marked "tools we already trust," and a policy does nothing about a door nobody is watching.

What watches the door is an inventory. Not a comprehensive, perfect, frozen catalog, which you will never finish and which would be stale the day you did. A living, honest list of where AI already touches your data: which of your existing tools have added AI features, which of those features are on, what data they reach, and whether anyone reviewed the terms after the feature shipped. This is unglamorous work. It is also the only thing that turns a blind spot into something you can govern. You cannot apply a policy to a system you cannot see. The inventory is what makes the system visible. In that sense the inventory is the control, and the policy is the paperwork the control makes enforceable.

Here is what this means in practice. First, change what triggers a review. Stop treating "new vendor" as the only event worth assessing, and start treating "existing vendor added AI" as an event too. The signal is sitting in those product update emails everyone deletes unread. Someone should be reading them with governance eyes. Second, go ask your current vendors three plain questions: what AI features are now in the product, are they on by default, and what happens to our data when they run. The answers will tell you more about your real exposure than any policy draft. Third, revisit the data processing terms for your highest-stakes tools, the ones holding the data that would hurt people if it leaked. If the AI feature is newer than the contract, the contract needs another look, and possibly a renegotiation.

None of this requires a large team or a new platform. It requires a change in where we point our attention. We have been guarding the formal entrance, the AI project that announces itself, while the capability walks in through a side door we propped open ourselves years ago when we approved the tool and trusted it to stay the same.

The privacy lead who read that vendor email did the right thing next. She did not panic, and she did not file it away. She started a list. One row at first: the CRM, the new assistant, on by default, donor data in scope, terms not yet reviewed. By the end of the week the list had eleven rows. Not because the organization had suddenly adopted AI, but because it always had been, one quiet update at a time, and now someone was finally looking.

The question worth sitting with is not whether your organization uses AI. You already know the answer is yes, somewhere. The question is how many rows your list would have if you started it today, and who in your organization is positioned to even know.